PT-2024-18395 · Mattermost · Mattermost

Eva Sarafianou

·

Published

2024-02-29

·

Updated

2025-05-12

·

CVE-2024-1888

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Mattermost versions prior to v8.1.9
Description Mattermost fails to check the invite guest permission when inviting guests of other teams to a team, allowing a member with permissions to add other members but not to add guests to add a guest to a team as long as the guest was already a guest in another team of the server.
Recommendations For versions prior to v8.1.9, update to version v8.1.9 or later to resolve the issue. As a temporary workaround, consider restricting the use of the invite guest permission to minimize the risk of exploitation.

Fix

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-1888
GHSA-PFW6-5RX3-XH3C
GO-2024-2593

Affected Products

Mattermost